<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>Peakhour.IO - Interest</title><link href="https://www.peakhour.io/" rel="alternate"></link><link href="https://www.peakhour.io/feeds/interest.atom.xml" rel="self"></link><id>https://www.peakhour.io/</id><updated>2025-11-18T21:00:00+11:00</updated><entry><title>Cloudflare outage proves Plan B depends on controlling DNS</title><link href="https://www.peakhour.io/blog/cloudflare-outage-dns-plan-b/" rel="alternate"></link><published>2025-11-18T21:00:00+11:00</published><updated>2025-11-18T21:00:00+11:00</updated><author><name>Dan</name></author><id>tag:www.peakhour.io,2025-11-18:/blog/cloudflare-outage-dns-plan-b/</id><summary type="html">&lt;p&gt;Tuesday’s Cloudflare incident reminded everyone that you can’t execute a Plan B if your DNS knobs are trapped behind the provider that’s failing. Here’s how Peakhour runs a detect-decide-divert playbook without touching your existing third-party DNS vendors.&lt;/p&gt;</summary><content type="html">&lt;p&gt;On Tuesday, 18 November 2025, Cloudflare’s own status page marked every major service—CDN, Firewall, WARP, Workers, and the dashboard—as degraded for most of the day while engineers worked through an internal control-plane failure. The timeline moved from “Investigating” at 11:48 UTC to “Monitoring” after 14:42 UTC, and the incident wasn’t officially resolved until 19:28 UTC. During the worst of it, Cloudflare disabled WARP in London, bot scores seesawed, and customers were told to wait while remediation continued.&lt;/p&gt;
&lt;p&gt;Waiting was the only option for many teams because their Plan B lived behind the same dashboard that was timing out. The top comment on the Hacker News thread was a set of &lt;code&gt;curl&lt;/code&gt; commands for moving domains off Cloudflare’s proxy edge. Admins were stuck in 2FA flows trying to fetch an API token, or searching for Terraform credentials so they could toggle a proxied flag. That is not a resilience strategy.&lt;/p&gt;
&lt;p&gt;We learned this lesson the hard way—and wrote about it after the 2021 Fastly outage in &lt;a href="/blog/fastly-outage-how-to-have-a-plan-b"&gt;How to have a Plan B&lt;/a&gt;. The rule still stands: the platform you are trying to leave cannot be the only place that can change where your DNS points.&lt;/p&gt;
&lt;h2&gt;Detect: understand what’s actually broken&lt;/h2&gt;
&lt;p&gt;Incidents like Tuesday’s change shape quickly. Cloudflare’s own feed showed different failure domains every 30 minutes: bot management, dashboard auth, Access, WARP. The first mile is impartial telemetry that tells you what your users feel, not what the provider thinks. At Peakhour we stream real user monitoring, synthetic checks, and control-plane health from multiple CDNs and DNS partners. That lets us distinguish “cache errors in Hong Kong” from “global auth outage” and choose the right lever.&lt;/p&gt;
&lt;h2&gt;Decide: keep DNS authority in neutral territory&lt;/h2&gt;
&lt;p&gt;When your domain delegation lives with agnostic providers—Route 53, NS1, Azure DNS, or the enterprise registrar your legal team already approved—you can make failover decisions without pleading with a failing control plane. Peakhour doesn’t replace those vendors; we orchestrate them. We set short-but-safe TTLs, keep secondary answers staged, and continuously audit API access so we can flip traffic with one signed request. The minute you outsource DNS authority to a proxy CDN, you have given up the control that makes Plan B possible.&lt;/p&gt;
&lt;h2&gt;Divert: run the playbook in minutes, not hours&lt;/h2&gt;
&lt;p&gt;A workable Plan B has three moves:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Pre-stage alternate edges.&lt;/strong&gt; Your secondary CDN, origin, or transit provider must be in sync with the active one—certificates, cache rules, WAF policies, everything. We keep them hot by replaying production configs across vendors.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Wire DNS automation.&lt;/strong&gt; We integrate with multiple third-party DNS APIs at once so we can update apex A/AAAA, flattened CNAMEs, and geo/latency rules in a single workflow. Because the automation lives off the impacted platform, we can execute even while Cloudflare’s dashboard is returning 500s.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Drill humans on the handoff.&lt;/strong&gt; Our SOC sits in Sydney and Melbourne, but we cover global hours. During an incident we line up Slack/Teams bridges with your SREs, confirm business impact, and keep execs in the loop while traffic drains to the healthy provider.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;With that in place we routinely hit sub-five-minute diversion times, including DNS propagation, because the decision, the tooling, and the people are ready before the outage hits.&lt;/p&gt;
&lt;h2&gt;What Peakhour brings to your Plan B&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Independent authority, familiar vendors.&lt;/strong&gt; We leverage multiple established DNS providers instead of locking you into ours. You keep your contracts; we bring the automation and guardrails.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Unified multi-CDN config.&lt;/strong&gt; Cache rules, image optimisation, WAF, and routing policies stay aligned across providers so you don’t lose capabilities when you switch.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Real drills, not just runbooks.&lt;/strong&gt; Quarterly failover exercises prove that certificates, APIs, and humans are ready. We share the post-mortems so your execs see clear RTO/RPO numbers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;People you can phone.&lt;/strong&gt; 24×7 Australian-based engineers who know your stack and can execute the play while your own team communicates with customers.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Book a resilience review&lt;/h2&gt;
&lt;p&gt;If Tuesday exposed that your failover path still depends on your primary provider’s dashboard, book a 30-minute Resilience Review with Peakhour and we’ll:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Map who really controls your DNS today.&lt;/li&gt;
&lt;li&gt;Identify the gaps between your primary and standby CDNs.&lt;/li&gt;
&lt;li&gt;Outline the automations we can layer on top of your existing DNS and hosting vendors.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The output is a concrete Plan B, a drill schedule, and a team that can execute it the next time a global provider blinks.&lt;/p&gt;</content><category term="Interest"></category><category term="CDN"></category><category term="DNS"></category><category term="Multi CDN"></category><category term="Incident Response"></category></entry><entry><title>Why Don't We Have an AI UI Yet?</title><link href="https://www.peakhour.io/blog/why-no-ai-interface-yet/" rel="alternate"></link><published>2025-07-20T00:00:00+10:00</published><updated>2025-07-20T00:00:00+10:00</updated><author><name>AC</name></author><id>tag:www.peakhour.io,2025-07-20:/blog/why-no-ai-interface-yet/</id><summary type="html">&lt;p&gt;If AI is the next great computer interface, why are we still clicking on icons and navigating menus? Exploring the major hurdles standing between us and a true AI-native operating system.&lt;/p&gt;</summary><content type="html">&lt;p&gt;In my last post, I made the case that Artificial Intelligence is the next great computer interface: a way to translate our intentions directly into actions. It is a powerful idea, but it immediately raises the practical question. If this is the future, where is it? Why am I still clicking icons and navigating menus on my computer instead of just talking to it?&lt;/p&gt;
&lt;p&gt;The concept is much cleaner than the implementation. We are still a fair way from having a true AI-native interface, and there are some hard problems to solve before it becomes the main way we use a computer.&lt;/p&gt;
&lt;h3&gt;The Understanding Problem&lt;/h3&gt;
&lt;p&gt;The first challenge is that current AIs don't truly &lt;em&gt;understand&lt;/em&gt; things in the way humans do. When you ask an AI to "write a summary of last quarter's sales," it doesn't know what a "sale" is or what a "quarter" means to the business. It is an extremely capable pattern-matching machine that knows which words and concepts are statistically likely to follow your request.&lt;/p&gt;
&lt;p&gt;That is useful for generating text or code, but it can also lead to "hallucinations"—where the AI confidently makes things up. For a chatbot, that might be annoying. For a computer's operating system, it is a critical failure. You can't have an interface that might invent a file that doesn't exist or misinterpret a crucial command.&lt;/p&gt;
&lt;h3&gt;The Action and Safety Problem&lt;/h3&gt;
&lt;p&gt;An AI interface needs to do more than just talk; it needs to &lt;em&gt;act&lt;/em&gt;. It must be able to open programs, manage files, change settings, and send emails. That requires giving the AI deep access to the core functions of the operating system, which is where the idea stops feeling neat and starts feeling risky.&lt;/p&gt;
&lt;p&gt;How do you give an AI the power to delete files based on a verbal command without creating a massive security hole? How do you ensure it can't be tricked by a cleverly worded prompt (or an external attacker) into causing chaos on your system? Creating a safe and reliable bridge between the AI's language processing and the computer's functions is a hard engineering problem.&lt;/p&gt;
&lt;h3&gt;The Trust and Reliability Problem&lt;/h3&gt;
&lt;p&gt;For an AI interface to be useful, we have to trust it completely. If you tell it to "delete my old holiday photos from 2018," you need to be certain it won't misunderstand and delete your wedding photos or important work documents.&lt;/p&gt;
&lt;p&gt;This need for absolute reliability runs counter to the probabilistic nature of today's AI models. We can't have an interface that is "mostly right." It needs to be right every single time. The hard part is adding the necessary safeguards and confirmation steps without turning the whole thing into a slower version of the menus we were trying to escape.&lt;/p&gt;
&lt;h3&gt;The Speed and Cost Problem&lt;/h3&gt;
&lt;p&gt;Finally, there is a practical issue. Running the massive language models that would power such an interface is slow and computationally expensive. A good user interface needs to feel instant and responsive. If it takes ten seconds for an AI to process your request to open a web browser, it is not a better experience than just clicking the icon yourself. The hardware and software infrastructure isn't quite ready to deliver the seamless, real-time experience we would expect from a primary computer interface.&lt;/p&gt;
&lt;p&gt;These challenges aren't insurmountable, but they are significant. That is why I think AI will keep showing up first as powerful features within our existing apps and operating systems. Those narrower uses give it clearer jobs, tighter permissions, and more places for humans to confirm what is about to happen. The full AI interface may arrive eventually, but I don't think it appears all at once. It will earn trust in smaller pieces first.&lt;/p&gt;</content><category term="Interest"></category><category term="Machine Learning"></category></entry><entry><title>AI as the Translator Between Human and Machine</title><link href="https://www.peakhour.io/blog/ai-the-next-interface/" rel="alternate"></link><published>2025-07-19T00:00:00+10:00</published><updated>2025-07-19T00:00:00+10:00</updated><author><name>AC</name></author><id>tag:www.peakhour.io,2025-07-19:/blog/ai-the-next-interface/</id><summary type="html">&lt;p&gt;We've gone from command lines to graphical interfaces. The next great leap in how we interact with computers won't be seen, it will be understood. AI is poised to become the ultimate translator between human intent and machine execution.&lt;/p&gt;</summary><content type="html">&lt;p&gt;Think about how we've talked to computers over the years. At first, it was rigid and unforgiving. The command line expected the exact words, in the exact order. One typo, and you were met with an error. It was powerful, but only once you learned to speak the computer's language.&lt;/p&gt;
&lt;p&gt;Then came the graphical user interface, or GUI—the familiar world of windows, icons, and mouse pointers. That changed the relationship. You no longer had to memorise commands before you could do something useful. You could see your options, click on them, and drag things around. It made computers accessible to hundreds of millions of people because it was more intuitive. It was a visual conversation.&lt;/p&gt;
&lt;p&gt;But both of these interfaces, the command line and the GUI, share the same basic bargain: we adapt ourselves to the computer. We still have to navigate menus, find the right button, or remember a specific command. We take a goal in our head and break it into steps the computer understands.&lt;/p&gt;
&lt;p&gt;What if that translation was no longer mainly our job? What if the computer could understand our goal well enough to work out the steps?&lt;/p&gt;
&lt;p&gt;This is the next shift I find interesting, and it is powered by Artificial Intelligence. AI is starting to look less like another application and more like the next major interface. It's not a visual one with buttons and menus, but an intelligent one built on understanding.&lt;/p&gt;
&lt;p&gt;The idea is simple, even if the implementation is not: we state our intent, and the AI figures out the steps. Instead of clicking through five different menus to create a sales report, you could just say, "Show me last quarter's sales figures for the eastern region, and visualise it as a bar chart." The AI's job is to understand that request and then do the work: query the database, aggregate the data, select the right chart type, and present it to you. It acts as a translator between human language and the computer's machine language.&lt;/p&gt;
&lt;p&gt;We're already seeing the early stages of this. When you ask a smart assistant to play a song, or when an AI co-pilot writes code for you, you're using an intent-driven interface. You're not telling it &lt;em&gt;how&lt;/em&gt; to do the task; you're just telling it &lt;em&gt;what&lt;/em&gt; you want done.&lt;/p&gt;
&lt;p&gt;That shift matters because it moves some of the cognitive load from us to the machine. We no longer need to be experts in using a particular piece of software; we just need to be clear about what we want to achieve. This has the potential to democratise technology on a scale we've never seen before, making complex digital tools feel closer to a conversation than a training course.&lt;/p&gt;
&lt;p&gt;The future of computing isn't about learning more complex systems. It's about building systems that can learn from us. The interface of tomorrow won't be something we click on, but something we talk to, correct, and steer. That is the real change: technology that doesn't just follow instructions, but understands our goals.&lt;/p&gt;</content><category term="Interest"></category><category term="Bot Management"></category><category term="Machine Learning"></category><category term="DevSecOps"></category><category term="Technical"></category></entry><entry><title>From Research Paper to Running Code</title><link href="https://www.peakhour.io/blog/from-paper-to-code-with-ai/" rel="alternate"></link><published>2025-07-18T00:00:00+10:00</published><updated>2025-07-18T00:00:00+10:00</updated><author><name>AC</name></author><id>tag:www.peakhour.io,2025-07-18:/blog/from-paper-to-code-with-ai/</id><summary type="html">&lt;p&gt;Exploring how AI can dramatically accelerate the process of turning complex academic research into functional code, with examples from anomaly detection to small LLMs.&lt;/p&gt;</summary><content type="html">&lt;p&gt;In my last post, I talked about my journey from typing &lt;code&gt;format c:&lt;/code&gt; on an old DOS machine to collaborating with AI. The part I keep coming back to still feels slightly unreal: turning academic research papers directly into working code.&lt;/p&gt;
&lt;p&gt;For years, the hard part was the distance between academia and industry. A good idea could be locked inside a dense, equation-heavy paper, and turning it into a practical tool could take a team of specialists weeks or months. You had to understand the mathematics, translate it into logic, write the code, and then debug all the places where the theory met the real world.&lt;/p&gt;
&lt;p&gt;Now my process looks completely different. I'll find an interesting paper, give it to an AI like Gemini, and say, "code this for me". It is a conversation, not just a command. We go back and forth, clarifying ambiguities in the paper and refining the implementation. What used to take weeks of painstaking effort can now be prototyped in an afternoon.&lt;/p&gt;
&lt;p&gt;Here are a few examples from my own experiments.&lt;/p&gt;
&lt;h3&gt;Anomaly Detection&lt;/h3&gt;
&lt;p&gt;I recently came across a paper detailing a new statistical method for detecting anomalies in time-series data. In the past, I would have spent days just trying to get comfortable with the mathematical models before writing a single line of code. This time, I fed the PDF to the AI. Within minutes, it had parsed the document and produced a Python implementation of the core algorithm. It was not perfect on the first go, but it was a solid, working foundation that we could test and refine together. The AI handled the heavy lifting of translation, leaving me to focus on validating and applying the model.&lt;/p&gt;
&lt;h3&gt;Customer Journey Mapping&lt;/h3&gt;
&lt;p&gt;Another area I have been looking at is using data to understand customer behaviour. There are academic papers that model how users interact with a website or product, mapping out their journey from discovery to purchase. Implementing these models used to be a serious undertaking. Now, I can give the AI a paper on a new journey mapping technique, and it can generate the code to analyse server logs or user event data and produce the kind of insights the paper describes. That makes it much easier to experiment with new ways of understanding our customers.&lt;/p&gt;
&lt;h3&gt;Building Small Language Models&lt;/h3&gt;
&lt;p&gt;This is where it gets really interesting. We can use large language models (LLMs) to help build smaller, more specialised ones. I've been experimenting with research papers that propose new, efficient LLM architectures. I can give one of these papers to a large AI and have it help me write the code for the smaller architecture. There is a beautiful irony in using a massive AI to help create its smaller, more nimble cousins. It speeds up the cycle of innovation inside the AI field itself.&lt;/p&gt;
&lt;p&gt;For me, the important change is the shorter loop between reading an idea, testing it, and getting it into use. The friction between a theoretical concept and a working prototype has been reduced almost to zero. That means I can explore more ideas, take more risks, and bring those research ideas into real use much faster than before.&lt;/p&gt;</content><category term="Interest"></category><category term="DevSecOps"></category><category term="Technical"></category><category term="Machine Learning"></category></entry><entry><title>My Programming Journey</title><link href="https://www.peakhour.io/blog/my-programming-journey-from-dos-to-ai/" rel="alternate"></link><published>2025-07-17T00:00:00+10:00</published><updated>2025-07-17T00:00:00+10:00</updated><author><name>AC</name></author><id>tag:www.peakhour.io,2025-07-17:/blog/my-programming-journey-from-dos-to-ai/</id><summary type="html">&lt;p&gt;A personal journey through the evolution of programming, from the early days of DOS and BASIC to the current age of AI-assisted coding.&lt;/p&gt;</summary><content type="html">&lt;p&gt;My path into technology started with a beige box and no plan beyond seeing what it would do.&lt;/p&gt;
&lt;p&gt;When I was a kid, I got an old 8086 computer. The only thing it came with was a thick manual for 'DOS', its operating system. For a child trying to make sense of it, the blinking &lt;code&gt;C:\&amp;gt;&lt;/code&gt; prompt was not exactly welcoming. What was I meant to do with it?&lt;/p&gt;
&lt;p&gt;I tried typing whatever came to mind, but most of it ended in errors. Then I stumbled on a command that actually did something interesting: &lt;code&gt;format c:&lt;/code&gt;. After I typed 'Y' to confirm, the screen would fill with text, showing me its progress. I didn't realise I was wiping the computer's entire memory. I only knew the machine was finally responding.&lt;/p&gt;
&lt;p&gt;Things properly opened up when I found a book filled with GW-BASIC programs. I wasn't just using a computer anymore; I was telling it what to do. I spent ages carefully typing out code, one line at a time. &lt;code&gt;10 PRINT "HELLO THERE"&lt;/code&gt;, &lt;code&gt;20 GOTO 10&lt;/code&gt;. It was slow work, but there was something hard to beat about bringing a program to life with my own hands.&lt;/p&gt;
&lt;p&gt;My skills moved along when QuickBasic started coming with MS-DOS. The tools were better, the language was more powerful, and I started building my own little games and applications, learning how to organise my ideas into code.&lt;/p&gt;
&lt;p&gt;Every programmer eventually hits a wall. For me, it was a 64-kilobyte limit on a single variable. It sounds tiny now, but it blocked a project I cared about. The only way forward was to learn C, a much more complex language. It was a hard jump, but it was the way to build bigger and more powerful software.&lt;/p&gt;
&lt;p&gt;That arc is why today's tools feel so strange to me.&lt;/p&gt;
&lt;p&gt;For most of my career, my job was to translate human ideas into instructions a computer could follow. I had to think like a machine, breaking everything down into small, logical steps.&lt;/p&gt;
&lt;p&gt;Now the process feels very different. I still solve problems, but I spend less time spelling out every instruction. I have a conversation with my computer. I can describe a goal, or show it a research paper, and an AI partner helps me write the code. My role has shifted from writing each line by hand to setting direction, checking the work, and deciding what is actually worth building.&lt;/p&gt;
&lt;p&gt;Looking back, the path from blindly typing &lt;code&gt;format c:&lt;/code&gt; to working alongside an AI still feels odd in the best way. We've moved from telling the machine exactly &lt;em&gt;how&lt;/em&gt; to do something to describing &lt;em&gt;what&lt;/em&gt; we want to achieve and then judging the result. That is a big change. I am still getting used to it.&lt;/p&gt;</content><category term="Interest"></category><category term="DevSecOps"></category></entry><entry><title>RFC 9460</title><link href="https://www.peakhour.io/blog/rfc-9460-dns-evolution/" rel="alternate"></link><published>2023-11-16T00:00:00+11:00</published><updated>2023-11-16T00:00:00+11:00</updated><author><name>AC</name></author><id>tag:www.peakhour.io,2023-11-16:/blog/rfc-9460-dns-evolution/</id><summary type="html">&lt;p&gt;Introducing SVCB and HTTPS records in DNS and their impact on web connectivity.&lt;/p&gt;</summary><content type="html">&lt;p&gt;RFC 9460 introduces two DNS record types: "SVCB" (Service Binding) and "HTTPS". They let browsers learn more connection details during DNS lookup, before redirects and TLS negotiation add extra steps. The result is cleaner connection setup, with practical improvements in speed, security, and efficiency.&lt;/p&gt;
&lt;h2&gt;Understanding the Current Process&lt;/h2&gt;
&lt;p&gt;Traditionally, when a browser connects to a website, it follows a sequence:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Browser requests site via HTTP.&lt;/li&gt;
&lt;li&gt;Server redirects request to HTTPS.&lt;/li&gt;
&lt;li&gt;Browser receives ALPN (Application-Layer Protocol Negotiation) during the HTTPS handshake.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The model is secure, but it is not optimal. It involves multiple round trips, which affects Time to First Byte (TTFB) and the overall user experience. Load balancing and failover are also less direct than they could be. RFC 9460 changes this by allowing DNS to provide the necessary connection details earlier. That reduces the steps involved in establishing a secure connection, lowering TTFB.&lt;/p&gt;
&lt;h2&gt;The Impact of SVCB and HTTPS Records&lt;/h2&gt;
&lt;p&gt;SVCB and HTTPS records move useful connection hints into DNS. They speed up the time-to-first-packet by incorporating the Alt-Svc HTTP header and ALPN TLS extension into DNS, which shortens connection setup. These records also enable redirection at the zone apex, a task not possible with CNAMEs. They simplify DNS load distribution and failover, making web services more resilient. They also remove the need for HSTS preloading and support Encrypted Client Hello (ECH), formerly ESNI, for better privacy.&lt;/p&gt;
&lt;h2&gt;Adoption and Industry Response&lt;/h2&gt;
&lt;p&gt;Adoption started before the RFC was finalised. Firefox has been conducting HTTPS lookups since May 2020, limited to DNS over HTTPS (DoH). Apple's iOS, Safari, and macOS have followed suit since September 2020. Chrome introduced partial support in December 2020 and has recently enabled ECH by default. Various DNS service providers have also started supporting HTTPS and SVCB records.&lt;/p&gt;
&lt;p&gt;As reported on &lt;a href="https://netmeister.org/blog/https-rrs.html"&gt;Netmeister&lt;/a&gt;, adoption is still early but not insignificant. As of October 2023, about 10 million domains have implemented an HTTPS record for their 'www' service names, roughly 4.4% of domains. Around 9.1 million domains, or about 4.0%, use the record on their bare second-level domain name. Among the top 1 million domains, approximately 22.5K (25.5%) use HTTPS records for 'www' service names, and nearly 24K (25.6%) use them on bare domains.&lt;/p&gt;
&lt;p&gt;&lt;img alt="October 2023 Usage" src="/static/images/blog/https-records-oct-2023.png"&gt;&lt;/p&gt;
&lt;h2&gt;What the Records Look Like&lt;/h2&gt;
&lt;p&gt;A typical &lt;a href="/learning/service-binding-record/"&gt;SVCB record&lt;/a&gt; might look like this:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;_example.com. 7200 IN SVCB 1 svc4.example.net. (alpn=&amp;quot;h2,h3&amp;quot; port=&amp;quot;8004&amp;quot;)
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;This record indicates that the service at &lt;code&gt;_example.com&lt;/code&gt; can be accessed at &lt;code&gt;svc4.example.net&lt;/code&gt; using either HTTP/2 or HTTP/3 on port 8004.&lt;/p&gt;
&lt;p&gt;An &lt;a href="/learning/https-record/"&gt;HTTPS record&lt;/a&gt; could be:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;example.com. 3600 IN HTTPS 0 svc.example.net.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;This record suggests that &lt;code&gt;example.com&lt;/code&gt; should be accessed securely through &lt;code&gt;svc.example.net&lt;/code&gt;.&lt;/p&gt;
&lt;h2&gt;Apex Domains and the Importance of SVCB/HTTPS Records&lt;/h2&gt;
&lt;p&gt;One long-running DNS limitation is the inability to use CNAME records at the apex (root level) of a domain due to conflicts with other necessary records like NS and SOA. RFC 9460's SVCB/HTTPS records address this by enabling apex domain aliasing without those conflicts. This matters for efficient content delivery networks (CDNs) and load balancing strategies.&lt;/p&gt;
&lt;h2&gt;These records enhance capability&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1. Load Balancing:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Consider a website that needs to distribute traffic across multiple servers. SVCB records can indicate different server endpoints with varying priorities.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;example.com. IN SVCB 10 server1.example.com. (alpn=&amp;quot;h2,h3&amp;quot;)
example.com. IN SVCB 20 server2.example.com. (alpn=&amp;quot;h2&amp;quot;)
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;In this example, &lt;code&gt;server1.example.com&lt;/code&gt; is the preferred endpoint (lower priority number), offering both HTTP/2 and HTTP/3 protocols. If it's unavailable, traffic automatically shifts to &lt;code&gt;server2.example.com&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Failover Mechanism:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;For a service that requires high availability, SVCB records can express failover directly:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;critical-service.example.com. IN SVCB 1 primary-service.example.com. (alpn=&amp;quot;h2,h3&amp;quot;)
critical-service.example.com. IN SVCB 2 backup-service.example.com. (alpn=&amp;quot;h2&amp;quot;)
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Here, &lt;code&gt;primary-service.example.com&lt;/code&gt; is the primary endpoint. If it fails, the system automatically falls back to &lt;code&gt;backup-service.example.com&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. Apex Domain Usage:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;A practical advantage of SVCB/HTTPS records is their ability to handle apex domains, where CNAME records are not feasible. This is important for root domain aliasing to different service providers.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;example.com. IN HTTPS 0 cdn-provider.example.net.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;This record indicates that the apex domain &lt;code&gt;example.com&lt;/code&gt; is to be served through &lt;code&gt;cdn-provider.example.net&lt;/code&gt;, overcoming traditional DNS limitations.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4. Encrypted ClientHello Support:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Future enhancements of SVCB could include keys for Encrypted ClientHello, which improves privacy and security during the initial TLS handshake.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;secure.example.com. IN SVCB 1 tls-service.example.net. (ech=&amp;quot;base64-encoded-key&amp;quot;)
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;This record can be used to initiate a TLS connection with &lt;code&gt;tls-service.example.net&lt;/code&gt; using the provided Encrypted ClientHello key.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;5. Directing Traffic to Specific Protocols:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;For services that need to direct clients to newer or more efficient protocols, SVCB records can specify the exact protocols to use.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;api.example.com. IN SVCB 1 api-server.example.com. (alpn=&amp;quot;h3&amp;quot;)
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Clients that understand HTTP/3 can connect directly using this protocol, bypassing the usual HTTP/1.1 or HTTP/2 protocols.&lt;/p&gt;
&lt;h2&gt;The Long Wait&lt;/h2&gt;
&lt;p&gt;HTTPS has been around for a while, so RFC 9460 raises an obvious question: why did this take so long? Apex records have had their share of problems, including not being able to use CNAMEs and having to resort to custom records like ALIAS or Cloudflare's 'cname flattening'.&lt;/p&gt;
&lt;p&gt;It is a fair question. We've had some bizarre records hanging around for ages along with a wide range of solutions to the "CNAME at the zone apex"
problem.&lt;/p&gt;
&lt;p&gt;Credit to the creators of RFC 9460 for getting this through and obtaining browser support:
   - B. Schwartz from Meta Platforms, Inc.
   - M. Bishop from Akamai Technologies
   - E. Nygren from Akamai Technologies&lt;/p&gt;
&lt;h2&gt;Final Thoughts&lt;/h2&gt;
&lt;p&gt;RFC 9460 gives DNS a more useful role in HTTPS connection setup. SVCB and HTTPS records let operators publish endpoint, protocol, failover, and privacy information before the browser starts negotiating the connection. That gives service providers more precise control over how clients reach web services, with practical benefits for performance, reliability, and security.&lt;/p&gt;</content><category term="Interest"></category><category term="HTTP"></category><category term="Web Performance"></category><category term="Rate Limiting"></category><category term="TLS Fingerprinting"></category><category term="CDN"></category><category term="DDoS"></category></entry><entry><title>Dive into CVSS Scores</title><link href="https://www.peakhour.io/blog/confluence-cvss-vectors/" rel="alternate"></link><published>2023-11-10T00:00:00+11:00</published><updated>2023-11-10T00:00:00+11:00</updated><author><name>AC</name></author><id>tag:www.peakhour.io,2023-11-10:/blog/confluence-cvss-vectors/</id><summary type="html">&lt;p&gt;Understand CVSS by examining the Atlassian CVE-2023-22515 and CVE-2023-22518.&lt;/p&gt;</summary><content type="html">&lt;h3&gt;Understanding CVSS through Atlassian Confluence Vulnerabilities&lt;/h3&gt;
&lt;p&gt;The Common Vulnerability Scoring System (CVSS) gives security teams a shared way to rate the severity of software vulnerabilities. It does not predict risk on its own; it describes the characteristics of a specific security flaw. CVSS uses three metric groups: Base, Temporal, and Environmental. The result is a score from 0 to 10, represented by a vector string that records the details behind the score.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Base Metrics&lt;/strong&gt; describe the inherent aspects of a vulnerability, including how it can be exploited and its potential system impact.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Temporal Metrics&lt;/strong&gt; change over time, reflecting current exploitability and available mitigations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Environmental Metrics&lt;/strong&gt; account for the specific environment where the vulnerability exists, tailoring the score to the affected organisation.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The &lt;a href="https://nvd.nist.gov/vuln-metrics/cvss"&gt;National Vulnerability Database (NVD)&lt;/a&gt; utilises CVSS to assign base scores and provides tools for calculating Temporal and Environmental scores.&lt;/p&gt;
&lt;h4&gt;Atlassian Confluence Vulnerability Analysis&lt;/h4&gt;
&lt;p&gt;Two Atlassian Confluence vulnerabilities show why the vector matters as much as the headline score:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CVE-2023-22515&lt;/strong&gt; is a critical flaw with a base score of 10.0. It is exploitable remotely, with low complexity, no privilege requirements, and no need for user interaction. The attack vector is network-based, so exposure is not limited to local access. Its broad scope and impact across confidentiality, integrity, and availability make it a vulnerability that needs immediate attention.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CVE-2023-22518&lt;/strong&gt; shares many similarities with CVE-2023-22515, including a critical base score of 10.0. It can also be exploited remotely without privileges or user interaction, and with low complexity. Its impact on the system's confidentiality, integrity, and availability is high, allowing attackers to gain complete control and shut down the affected resources.&lt;/p&gt;
&lt;p&gt;Both CVE-2023-22515 and CVE-2023-22518 are critical vulnerabilities that demand urgent remediation. Understanding their CVSS vectors helps prioritise the security response and the mitigations needed.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CVE-2023-22515&lt;/strong&gt; carries a CVSS score of 10 because it is remotely exploitable, easy to execute, and does not require privileges or user interaction.&lt;/p&gt;
&lt;h5&gt;CVSS Vector for CVE-2023-22515&lt;/h5&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Base Score:&lt;/strong&gt; 10.0 (Critical)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vector:&lt;/strong&gt; CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This vector indicates:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Attack Vector (AV): Network (N)&lt;/strong&gt; - The vulnerability is remotely exploitable.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Attack Complexity (AC): Low (L)&lt;/strong&gt; - It is easy to exploit without major obstacles.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Privileges Required (PR): None (N)&lt;/strong&gt; - No special access is needed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;User Interaction (UI): None (N)&lt;/strong&gt; - It can be exploited without user involvement.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Scope (S): Changed (C)&lt;/strong&gt; - The impact extends beyond the initial target.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Confidentiality, Integrity, Availability (C/I/A): High (H)&lt;/strong&gt; - There is a complete loss of confidentiality, integrity, and availability.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Atlassian's high CVSS score for CVE-2023-22515 reflects its critical nature and the need for immediate action.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CVE-2023-22518&lt;/strong&gt; has the same CVSS score of 10, with similar impact across confidentiality, integrity, and availability.&lt;/p&gt;
&lt;h5&gt;CVSS Vector for CVE-2023-22518&lt;/h5&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Base Score:&lt;/strong&gt; 10.0 (Critical)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vector:&lt;/strong&gt; CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This vector means:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Attack Vector (AV): Network (N)&lt;/strong&gt; - Exploitable remotely.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Attack Complexity (AC): Low (L)&lt;/strong&gt; - Easy to exploit with minimal barriers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Privileges Required (PR): None (N)&lt;/strong&gt; - No user privileges required.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;User Interaction (UI): None (N)&lt;/strong&gt; - No need for user action.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Scope (S): Changed (C)&lt;/strong&gt; - Broad impact beyond the initial system.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Confidentiality, Integrity, Availability (C/I/A): High (H)&lt;/strong&gt; - Complete compromise of the system's security.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Understanding the CVSS scores for these vulnerabilities helps teams prioritise their security response. For a full breakdown and history of CVSS, see &lt;a href="https://en.wikipedia.org/wiki/Common_Vulnerability_Scoring_System"&gt;Wikipedia&lt;/a&gt;. More detailed information on CVSS can also be found in &lt;a href="https://www.first.org/cvss/"&gt;FIRST's official CVSS documentation&lt;/a&gt;.&lt;/p&gt;</content><category term="Interest"></category><category term="Threat Detection"></category><category term="DevSecOps"></category><category term="Application Security"></category><category term="Anomaly Detection"></category><category term="Credential Stuffing"></category><category term="Core Web Vitals"></category></entry><entry><title>A Risk Based Approach To Vulnerability Scoring</title><link href="https://www.peakhour.io/blog/epss-explained/" rel="alternate"></link><published>2023-11-10T00:00:00+11:00</published><updated>2023-11-10T00:00:00+11:00</updated><author><name>AC</name></author><id>tag:www.peakhour.io,2023-11-10:/blog/epss-explained/</id><summary type="html">&lt;p&gt;An in-depth exploration of EPSS, its data-driven approach to assessing cybersecurity threats, and how it complements CVSS.&lt;/p&gt;</summary><content type="html">&lt;p&gt;The Exploit Prediction Scoring System (EPSS) estimates the likelihood that a published CVE will be exploited in the wild. Its value is that it brings several signals into one risk score, instead of treating every vulnerability with the same CVSS severity as equally urgent. The main inputs are:&lt;/p&gt;
&lt;h3&gt;Data Sources of EPSS&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;MITRE’s CVE List&lt;/strong&gt;: EPSS scores only vulnerabilities that are "published" on this list.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Text-based “Tags”&lt;/strong&gt;: Extracted from CVE descriptions and related discussions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Publication Duration&lt;/strong&gt;: The time period since the CVE was published.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reference Count&lt;/strong&gt;: The number of references in the CVE entry.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Published Exploit Code&lt;/strong&gt;: Code from platforms such as Metasploit, ExploitDB, or GitHub.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security Scanners&lt;/strong&gt;: Data from security tools such as Jaeles and Nuclei.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CVSS v3 Vectors&lt;/strong&gt;: Based on the base score in the National Vulnerability Database (NVD).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CPE (vendor) Information&lt;/strong&gt;: Details about the vendors of the products involved, also from NVD.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Ground Truth Data&lt;/strong&gt;: Real-world exploitation data from sources such as AlienVault.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;EPSS Model and Tools&lt;/h3&gt;
&lt;p&gt;The current EPSS model, version 2022.01.01, uses 1,164 variables and is based on Gradient Boosting, a machine learning technique. For a visual and interactive view of EPSS scores, the &lt;a href="https://holisticinfosec.shinyapps.io/epsscall/"&gt;EPSScall&lt;/a&gt; tool is useful. It provides historical data and graphs that make score movement easier to inspect.&lt;/p&gt;
&lt;h3&gt;The Drivers of EPSS Scores&lt;/h3&gt;
&lt;p&gt;To understand EPSS, it helps to look at which inputs carry the most weight. The variable importance graph shows the strongest contributors to the EPSS score.&lt;/p&gt;
&lt;p&gt;&lt;img alt="EPSS Variable Importance Graph" src="/static/images/blog/epss_variable_importance.png"&gt;&lt;/p&gt;
&lt;p&gt;Vendor data plays an outsized role in the scoring process. The graph shows how much weight each component has when estimating whether a vulnerability is likely to be exploited.&lt;/p&gt;
&lt;h2&gt;Why Does This Matter?&lt;/h2&gt;
&lt;p&gt;EPSS uses these data sources to predict exploit likelihood more directly than severity-only methods. By considering factors from the age of the CVE to real-world exploit instances, EPSS gives defenders a clearer view of which vulnerabilities are more likely to matter operationally. That makes patching and mitigation decisions easier to prioritise when resources are limited.&lt;/p&gt;
&lt;p&gt;Understanding the components of EPSS also makes the score easier to interpret. It is not a single severity metric; it is a blend of several data points, each with different weight. Tools like EPSScall make those inputs easier to inspect when tuning a vulnerability management process.&lt;/p&gt;
&lt;h2&gt;Final Thoughts&lt;/h2&gt;
&lt;p&gt;EPSS is useful because it shifts vulnerability triage away from severity alone and towards exploit likelihood. Its use of multiple data sources and machine learning makes it a practical tool for defenders who need to decide what to fix first. Prioritising vulnerabilities this way does not replace judgement, but it gives teams a stronger starting point than CVSS alone.&lt;/p&gt;</content><category term="Interest"></category><category term="Threat Detection"></category><category term="Application Security"></category><category term="DevSecOps"></category><category term="Anomaly Detection"></category><category term="DDoS"></category><category term="Credential Stuffing"></category></entry><entry><title>Navigating CDN Consolidation</title><link href="https://www.peakhour.io/blog/navigating-cdn-consolidation/" rel="alternate"></link><published>2023-11-01T00:00:00+11:00</published><updated>2023-11-01T00:00:00+11:00</updated><author><name>AC</name></author><id>tag:www.peakhour.io,2023-11-01:/blog/navigating-cdn-consolidation/</id><summary type="html">&lt;p&gt;Explore the complexities of switching CDN providers amid industry consolidation and how Peakhour can assist in the transition&lt;/p&gt;</summary><content type="html">&lt;p&gt;The &lt;a href="/learning/cdn/"&gt;CDN&lt;/a&gt; industry is moving quickly, with major providers such as Akamai and Cloudflare consolidating their positions. For businesses caught in that movement, changing CDN providers is rarely a simple swap. Your CDN sits in front of your website or application, so migration decisions touch performance, security, routing, caching, and operational risk.&lt;/p&gt;
&lt;h2&gt;Market Shifts in the CDN Industry&lt;/h2&gt;
&lt;p&gt;The CDN market is being reshaped by large providers and newer entrants. Akamai's acquisition of Linode is one example, expanding its cloud services and strengthening its position beyond CDN. Cloudflare is moving in a similar direction, adding cloud-based services around its CDN platform.&lt;/p&gt;
&lt;h2&gt;Akamai's Strategic Moves&lt;/h2&gt;
&lt;p&gt;Akamai has recently bought customer contracts from both Lumen and StackPath. This is likely to lift its 2024 revenue by tens of millions of dollars. The transferred customers will also benefit from Akamai’s wider cloud and security services.&lt;/p&gt;
&lt;p&gt;Azure CDN Standard from Akamai, StackPath CDN, and Lumen CDN are all going offline soon. Clients have received only 2-3 months' notice to migrate, which is a tight window for a service that usually has routing, security, caching, and origin dependencies. Vendors should avoid putting customers in this position. A multi-CDN strategy can reduce that exposure.&lt;/p&gt;
&lt;h2&gt;What Happened to Section.io?&lt;/h2&gt;
&lt;p&gt;Section.io, once a CDN, shifted to edge computing before being sold to Webscale. That leaves approximately 300 Australian websites looking for new service providers. If you are one of them, now is the time to act.&lt;/p&gt;
&lt;p&gt;These moves make the decision to switch or stay with a CDN provider more complex, especially for smaller businesses that need flexible and reliable local alternatives such as Peakhour. Switching your CDN is not as straightforward as changing a DNS record. Your CDN acts as the gateway to your website or application, so a move can involve reconfiguring a large part of the delivery stack.&lt;/p&gt;
&lt;h2&gt;Why Peakhour Is the Right Choice&lt;/h2&gt;
&lt;p&gt;Peakhour is a local, reliable alternative in an industry changing quickly. We offer the flexibility needed for customisation and a full suite of services.&lt;/p&gt;
&lt;p&gt;If you are considering a CDN switch, treat it as a technical migration rather than a procurement task. Peakhour can help make that transition smoother.&lt;/p&gt;
&lt;h2&gt;Peakhour's Top 10 Things to Consider When Changing Providers&lt;/h2&gt;
&lt;p&gt;Switching CDNs? Work through these ten factors before you move:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Caching Rules&lt;/strong&gt;: Use the migration to review and optimise your caching settings.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;POP Distribution&lt;/strong&gt;: Understand how the new CDN's points of presence may affect your traffic.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Security Gaps&lt;/strong&gt;: Evaluate how the new CDN's security measures compare to your current provider.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Access Lists&lt;/strong&gt;: Make sure IP whitelists and blacklists are carried over cleanly.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Origin Security&lt;/strong&gt;: Update IP addresses to ensure your origin server recognises the new CDN.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;SSL/TLS Certificates&lt;/strong&gt;: Confirm the new CDN supports your existing SSL/TLS settings and can carry over the certificates you need.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;API Compatibility&lt;/strong&gt;: Ensure the new CDN offers APIs that match or exceed your current usage.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Analytics and Monitoring&lt;/strong&gt;: Assess if the new CDN's analytics tools meet your needs.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Rate Limiting&lt;/strong&gt;: Review the new CDN's rate limiting options, especially if your site experiences traffic bursts.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Costs&lt;/strong&gt;: Account for migration work, potential downtime, and any hidden fees.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;Additional Considerations for a Seamless Transition&lt;/h2&gt;
&lt;p&gt;Beyond the top ten, also consider:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Bot Protection&lt;/strong&gt;: Evaluate how the new CDN manages automated traffic.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;User Agent Validation&lt;/strong&gt;: Make sure the new CDN effectively screens search engine bots.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;IP Reputation Lists&lt;/strong&gt;: Know how your new CDN updates and uses IP reputation lists.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;API Protection&lt;/strong&gt;: Confirm that the new CDN provides strong API security controls.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Dynamic Page Caching&lt;/strong&gt;: Check how the new CDN handles caching for dynamic content.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Query String Handling&lt;/strong&gt;: Understand how your new CDN treats query strings, as this can affect cache performance after migration.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;Special Concerns for E-commerce Sites&lt;/h2&gt;
&lt;p&gt;For e-commerce, also think about:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Site Integrations&lt;/strong&gt;: Does the new CDN support plugins for your platform, such as Magento?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Custom WAF Rules and Exceptions&lt;/strong&gt;: Ensure these can be moved to the new CDN.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Image Optimisation&lt;/strong&gt;: Update Image APIs if your CDN handles image transformations.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;Advanced Configurations&lt;/h2&gt;
&lt;p&gt;Advanced setups need closer review:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Origin Mounting&lt;/strong&gt;: Confirm your multiple origins will work as needed with the new CDN.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Request Routing&lt;/strong&gt;: Make sure you can replicate your existing routing configurations with the new provider.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Edge Redirects&lt;/strong&gt;: Ensure the new CDN can handle any redirects you’ve configured at the edge.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;</content><category term="Interest"></category><category term="CDN"></category><category term="Magento"></category><category term="Account Protection"></category><category term="DDoS"></category></entry><entry><title>Web scraping another Business' website</title><link href="https://www.peakhour.io/blog/is-it-legal-to-scrape-a-competitors-website/" rel="alternate"></link><published>2023-10-11T13:00:00+11:00</published><updated>2023-10-11T13:00:00+11:00</updated><author><name>Legalvision</name></author><id>tag:www.peakhour.io,2023-10-11:/blog/is-it-legal-to-scrape-a-competitors-website/</id><summary type="html">&lt;p&gt;Scraping competitor websites is a common practice, but is it legal? Read on to find out.&lt;/p&gt;</summary><content type="html">&lt;p&gt;As businesses continue to build their presence online, screen scraping is becoming more prevalent. Screen scraping is
the use of software or code to take data from another website. For example, popular platforms like Skyscanner or
booking.com usually take price data on flights and accommodation and display it on their websites. However, Australian
copyright laws or the website owner’s terms and conditions may forbid you from screen scraping. This article explains
the legal aspects of scraping data from another business’ website and the precautions you should take.&lt;/p&gt;
&lt;h2&gt;Am I Violating the Law by Screen Scraping?&lt;/h2&gt;
&lt;p&gt;Australian &lt;a href="https://legalvision.com.au/copyright/"&gt;copyright law&lt;/a&gt; safeguards ‘original creative works’, including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;written works;&lt;/li&gt;
&lt;li&gt;visual images;&lt;/li&gt;
&lt;li&gt;music; and&lt;/li&gt;
&lt;li&gt;moving images.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Copyright can also protect documents such as government reports and legal forms. When determining whether copyright
protects a creative work, the work does not need to be intricate or of high quality. It only needs to demonstrate
originality and not be copied from another source.&lt;/p&gt;
&lt;h2&gt;Is Data an ‘Original Work’?&lt;/h2&gt;
&lt;p&gt;Data is usually fact-based and primarily consists of statistics or numbers. As a result, copyright usually does not
protect data.&lt;/p&gt;
&lt;p&gt;Examples of such data include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;the consumer price index for a particular quarter;&lt;/li&gt;
&lt;li&gt;monthly house price increases in a city;&lt;/li&gt;
&lt;li&gt;the number of students in a class; or&lt;/li&gt;
&lt;li&gt;the count of films released in a year.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Generally, the law does not consider this an &lt;a href="https://legalvision.com.au/protect-your-idea/"&gt;original work&lt;/a&gt; because it
merely represents real-world information.&lt;/p&gt;
&lt;h2&gt;What Data is an ‘Original Work’?&lt;/h2&gt;
&lt;p&gt;However, data can be an original work in some circumstances. For example, if you organise data in a unique manner
that reflects someone's creativity, the law might consider that data an ‘original work’.&lt;/p&gt;
&lt;p&gt;Examples of organised data that copyright protects include;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;accounting forms;&lt;/li&gt;
&lt;li&gt;sequences of numbers or letters for a bingo game; or&lt;/li&gt;
&lt;li&gt;a car parts catalogue.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Consequently, screen scraping data from a website is unlikely to infringe copyright unless it involves protected,
creatively organised data. Infringing someone’s copyright means using their copyright-protected material without their
permission.&lt;/p&gt;
&lt;h2&gt;Are There Exceptions to Copyright Law?&lt;/h2&gt;
&lt;p&gt;In the rare event that your screen scraping infringes copyright, your use could fall under an exception to copyright
infringement. Australian copyright law refers to these exceptions as 'fair dealing.'&lt;/p&gt;
&lt;p&gt;The four ‘fair dealing’ exceptions include using copyright-protected materials for:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;research or study;&lt;/li&gt;
&lt;li&gt;review or critique;&lt;/li&gt;
&lt;li&gt;parody or satire; and&lt;/li&gt;
&lt;li&gt;reporting the news.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For instance, a journalist scraping original data sets to report potential price-gouging among airlines could
potentially rely on the exception for reporting the news. However, if you are scraping data for business purposes, the
fair dealing exceptions may not apply.&lt;/p&gt;
&lt;h2&gt;What if a Website Explicitly Bans Screen Scraping?&lt;/h2&gt;
&lt;p&gt;Even if screen scraping is not always illegal under Australian copyright law, website owners can use their terms of
use to prohibit data scraping. These terms of use often appear as website pop-ups. The pop-ups typically state that by
continuing to use the website, you accept the terms of use.&lt;/p&gt;
&lt;p&gt;These terms can explicitly forbid:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;data scraping;&lt;/li&gt;
&lt;li&gt;copying;&lt;/li&gt;
&lt;li&gt;hacking; or&lt;/li&gt;
&lt;li&gt;any form of data extraction.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Violating these terms would result in you breaching the website’s
&lt;a href="https://legalvision.com.au/what-is-a-websites-terms-of-use-document/"&gt;terms of use&lt;/a&gt;. As a result, the website owner
may take legal action against you. If the data on the website qualifies as original work, copyright infringement claims
may also arise.&lt;/p&gt;
&lt;p&gt;Therefore, it is advisable not to screen scrape from websites with explicit terms of use against that activity. If you
do engage in screen scraping, ensure you only extract factual information.&lt;/p&gt;
&lt;h2&gt;Key Takeaways&lt;/h2&gt;
&lt;p&gt;Screen scraping is generally lawful if you extract strictly factual information from other websites. However, if a
website's terms of use prohibit screen scraping, even for factual data, it is advisable to avoid data scraping.
Otherwise, you could face potential breach of contract and copyright infringement claims.&lt;/p&gt;
&lt;p&gt;For assistance with your legal obligations, LegalVision’s experienced &lt;a href="https://legalvision.com.au/it-lawyer/"&gt;IT lawyers&lt;/a&gt;
can assist as part of their membership. For a low monthly fee, you will have unlimited access to lawyers who can
answer your questions and draft and review your documents. Call LegalVision today on 1800 296 912 or visit their
&lt;a href="https://legalvision.com.au/membership/"&gt;membership page&lt;/a&gt;.&lt;/p&gt;</content><category term="Interest"></category><category term="Browser Fingerprinting"></category><category term="Residential Proxies"></category></entry><entry><title>A Secure Internet</title><link href="https://www.peakhour.io/blog/chrome-https-default-experiment/" rel="alternate"></link><published>2023-08-16T00:00:00+10:00</published><updated>2023-08-16T00:00:00+10:00</updated><author><name>AC</name></author><id>tag:www.peakhour.io,2023-08-16:/blog/chrome-https-default-experiment/</id><summary type="html">&lt;p&gt;Google Chrome is advancing towards making the web secure by default through HTTPS-First Mode.&lt;/p&gt;</summary><content type="html">&lt;p&gt;Here at Peakhour, we track browser security changes because they affect how sites are delivered and how users experience
warnings. Google Chrome has made another move towards encrypted and authenticated traffic by expanding HTTPS-First Mode.
Here is what Chrome unveiled on August 16, 2023, and what it means for HTTPS by default.&lt;/p&gt;
&lt;h2&gt;Automatic Upgrades to HTTPS&lt;/h2&gt;
&lt;p&gt;Chrome aims to make HTTPS the standard protocol by automatically upgrading all HTTP navigations to HTTPS. Even if you
click a link explicitly declaring HTTP, Chrome will try HTTPS first. If the upgrade fails because of an invalid
certificate or another issue, Chrome will fall back to HTTP.&lt;/p&gt;
&lt;p&gt;The change is part of an experiment in Chrome version 115. It does not protect against active network attackers, but it
does shift more everyday traffic away from passive eavesdropping and towards HTTPS as the default.&lt;/p&gt;
&lt;h2&gt;Warning on Insecurely Downloaded Files&lt;/h2&gt;
&lt;p&gt;Chrome is also adding warnings before users download high-risk files over insecure connections. Downloaded files can
contain malicious code that compromises a computer. The warning gives users a clearer signal before they proceed, while
still allowing the download if they accept the risk. The rollout of these warnings is expected to start in mid-September.&lt;/p&gt;
&lt;h2&gt;Expanding HTTPS-First Mode Protections&lt;/h2&gt;
&lt;p&gt;Chrome's longer-term goal is to enable HTTPS-First Mode for all users. It is expanding those protections in several
areas:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Enabling HTTPS-First Mode for users in Google's Advanced Protection Program who are also signed into Chrome.&lt;/li&gt;
&lt;li&gt;Planning to enable HTTPS-First Mode by default in Incognito Mode for a more secure browsing experience.&lt;/li&gt;
&lt;li&gt;Experimenting with automatically enabling HTTPS-First Mode on sites frequently accessed over HTTPS.&lt;/li&gt;
&lt;li&gt;Exploring automatically enabling HTTPS-First Mode for users who rarely use HTTP.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Try it Out&lt;/h2&gt;
&lt;p&gt;For users who want to try HTTPS upgrading or insecure download warnings before the full rollout, Chrome has provided
options in the browser's settings to enable these features.&lt;/p&gt;
&lt;h2&gt;Peakhour's HTTPS Redirection Feature at the Edge&lt;/h2&gt;
&lt;p&gt;At Peakhour, HTTPS redirection is a practical edge control. It helps enforce encrypted and authenticated connections
before a request reaches the origin.&lt;/p&gt;
&lt;p&gt;When a user attempts to access a site over HTTP, our edge identifies the unsecured connection. Instead of allowing that
connection through, we redirect the request to the HTTPS version of the site.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Enhanced Security&lt;/strong&gt;: By enforcing HTTPS, data transmitted between your website and your users is encrypted and
   protected from potential attackers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Compliance with Best Practices&lt;/strong&gt;: This feature aligns with industry standards and recent browser policies, including
   Chrome's push towards HTTPS-first mode.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;User Trust&lt;/strong&gt;: A secure connection gives users a clearer reason to trust the site, improving the user experience and
   potentially supporting higher conversion rates.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;We also offer options for customisation, allowing you to set specific rules and behaviours for how HTTP requests are
handled and redirected to HTTPS. Peakhour's HTTPS redirection feature at the edge is a small control with a clear job:
move HTTP traffic onto HTTPS automatically, protect users, and keep sites aligned with current browser expectations.&lt;/p&gt;
&lt;h2&gt;Final Thoughts&lt;/h2&gt;
&lt;p&gt;Chrome's push towards a secure-by-default web is another step towards a fully encrypted and authenticated internet. It
also matches the way Peakhour thinks about everyday security controls: enforce the basics at the edge, and make the safe
path the default.&lt;/p&gt;
&lt;p&gt;Chrome's changes may require developers, enterprises, and users to adapt. The direction is still clear: less plain HTTP,
more HTTPS by default, and fewer silent insecure paths. If your organisation is reviewing its HTTP handling, Peakhour can
help you apply the right redirects and edge rules.&lt;/p&gt;</content><category term="Interest"></category><category term="TLS"></category><category term="HTTP"></category></entry><entry><title>Down But Not Out - JXL Will Return on Safari</title><link href="https://www.peakhour.io/blog/jpeg-xl-down-but-not-out/" rel="alternate"></link><published>2023-06-04T00:00:00+10:00</published><updated>2023-06-04T00:00:00+10:00</updated><author><name>AC</name></author><id>tag:www.peakhour.io,2023-06-04:/blog/jpeg-xl-down-but-not-out/</id><summary type="html">&lt;p&gt;What Apple's announcement of JPEG-XL support means for the web ecosystem.&lt;/p&gt;</summary><content type="html">&lt;p&gt;Just as we were &lt;a href="/blog/the-death-of-jxl/"&gt;coming to terms&lt;/a&gt; with the controversial decision by Google to drop support for JPEG-XL (JXL) in Chrome,
Apple announced support for JXL during the WWDC June 5th livestream. That is a meaningful shift. JXL was down, but not
out.&lt;/p&gt;
&lt;p&gt;Google's decision to stop JXL support in Chrome surprised us at Peakhour, along with plenty of others who care about
web performance and image delivery. Google Chrome, as the most used browser globally, often sets the course for web
standards. In deciding to drop JXL, Google appeared to be exercising its dominance over those standards, and the decision
drew real debate in the web community.&lt;/p&gt;
&lt;p&gt;Apple's announcement changes the picture. Apple has long pushed high dynamic colour and high-resolution features, and
Safari support is a useful signal for image delivery. By bringing JXL support to Safari, Apple is giving this promising
image format a fair go.&lt;/p&gt;
&lt;p&gt;This move also hints at wider JXL support across the entire Apple ecosystem, which includes iPad, iPhone, Mac, and Apple
TV. While there are still some limitations - embedded colour profiles and animations are not yet supported in the
current MacOS Sonoma beta - we hope these gaps are fixed soon.&lt;/p&gt;
&lt;p&gt;At Peakhour, this is good news. We look forward to welcoming Apple users to our websites, where they will be able to see
the quality benefits of JXL images as soon as their operating systems support it.&lt;/p&gt;
&lt;p&gt;This turn of events gives JXL a much-needed boost. It does not undo Google's Chrome decision, but it keeps the format in
play and makes the future of web image formats less settled than it looked a short while ago.&lt;/p&gt;</content><category term="Interest"></category><category term="Core Web Vitals"></category><category term="Browser Fingerprinting"></category><category term="CDN"></category></entry><entry><title>Fastly Outage</title><link href="https://www.peakhour.io/blog/fastly-outage-how-to-have-a-plan-b/" rel="alternate"></link><published>2021-06-09T13:00:00+10:00</published><updated>2021-06-09T13:00:00+10:00</updated><author><name>Dan</name></author><id>tag:www.peakhour.io,2021-06-09:/blog/fastly-outage-how-to-have-a-plan-b/</id><summary type="html">&lt;p&gt;Fastly, a major CDN provider, had a global outage last night which affected some of the world's largest websites and internet services. Why didn't they have a backup plan?&lt;/p&gt;</summary><content type="html">&lt;p&gt;You may have heard that Fastly, one of the world’s largest providers of &lt;a href="/learning/cdn/"&gt;CDN&lt;/a&gt; services, had an outage of about 1 hour on
the 8th July. Some of the world's largest websites and services were down, including reddit, CNN, The Guardian,
Shopify Stores, Stripe and Spotify, to name a few.&lt;/p&gt;
&lt;p&gt;According to Fastly themselves, the outage was caused by a 'service misconfiguration' (Update: Bug triggered by a client
changing their configuration), which propagated globally and took websites offline. When users tried to access a website
using the Fastly service, they were presented with a Varnish 503 Guru Meditation error (for those of us old enough to
remember, Guru Meditation is a geek reference to the Commodore Amiga computer of the late 80s!). This generally occurs
when there is an issue contacting the server that the website is actually hosted on. There were also some reports on
twitter saying 'unknown domain'.&lt;/p&gt;
&lt;p&gt;Essentially, Fastly took down its own network with a bad software update. Similar problems have affected other online
platforms in the recent past, including Google, Amazon, and Cloudflare.&lt;/p&gt;
&lt;h2&gt;Why wasn’t there a Plan B?&lt;/h2&gt;
&lt;p&gt;Fastly is an excellent service, with an enviable reliability record. There is a reason why they're trusted by some of
the world's largest websites to improve reliability and load times. However, the vast majority of Fastly clients still
had to sit tight and wait for Fastly to fix the issue. Luckily this was &lt;strong&gt;only&lt;/strong&gt; an hour. It could have been much longer.&lt;/p&gt;
&lt;p&gt;Just like death and taxes, software outages are a certainty. The real story is not that Fastly had an outage. It is
&lt;strong&gt;why didn't these large websites have a contingency plan for a single point of failure&lt;/strong&gt;. For sites at that scale, this
is a major oversight in infrastructure planning.&lt;/p&gt;
&lt;h2&gt;How to handle a CDN failure&lt;/h2&gt;
&lt;p&gt;The simple solution is to have a backup CDN provider already configured and tested, ready to switch over to if your
primary provider fails. You can then utilise short expiry of DNS records to redirect users when the failure happens. This
needn't be very expensive or complicated, although individual circumstances vary.&lt;/p&gt;
&lt;h3&gt;A Quick Introduction To DNS (Domain Name System)&lt;/h3&gt;
&lt;p&gt;Modern CDNs, like Fastly, Cloudflare, and Peakhour, operate as ‘reverse proxies’. This means they sit between a website's
end users and the website server itself. They achieve this through DNS configuration.&lt;/p&gt;
&lt;p&gt;When someone types a domain url into a browser, eg fastly.com, a request is sent to a DNS server with the host name
(eg fastly.com) to find the IP address of the server to retrieve the content from. CDNs, like Fastly, get website admins
to list the address of the CDN on the DNS server. That means requests for a website go through the CDN first.
The process is analogous to listing someone else’s number in the phone book so they take calls for you.&lt;/p&gt;
&lt;p&gt;The DNS server has a TTL (Time To Live) associated with its records. This TTL tells whoever asked for an IP address,
for a given hostname, to remember the answer and not ask again until after the TTL has passed. Typically DNS record
TTLs will be 1 hour, but they can be shorter, eg 1 minute.&lt;/p&gt;
&lt;h3&gt;Switching providers in case of an outage&lt;/h3&gt;
&lt;p&gt;By keeping a short TTL in DNS, webmasters can switch the answer for a DNS request to that of another provider, meaning
users can quickly be directed to an alternative Cloud Provider. Once service has resumed on the primary provider, DNS can
be switched again so normal traffic is resumed. The key is that the alternative provider is configured, tested, and ready
to go.&lt;/p&gt;
&lt;p&gt;This switch can even be automated to minimise outages. Premium DNS services, like Amazon’s Route 53, have optional health
checking of DNS answers. This allows a switch to happen nearly instantly. The only downtime would be for people already
on the site who have to wait for the TTL to expire before being directed to the backup Cloud Provider. In fact this is
exactly what Peakhour.io does. In the event of a catastrophic outage we use DNS to switch to backup infrastructure so our
clients are minimally affected.&lt;/p&gt;
&lt;h3&gt;Backup provider options&lt;/h3&gt;
&lt;p&gt;Now we've shown how switching CDN providers can be done, let's compare the major players and how they might serve as a
backup CDN for Fastly. The three things we'll look at are Cost, Features, Integration.&lt;/p&gt;
&lt;h4&gt;Simply route traffic to the origin&lt;/h4&gt;
&lt;p&gt;This would be the simplest and most cost effective option, &lt;strong&gt;Assuming&lt;/strong&gt; your origin server can handle the increased load
that removing its CDN would entail. It also assumes that it's ok to lose any features that you may have been relying on,
eg load balancing, WAF, edge scripting, image optimisation etc.&lt;/p&gt;
&lt;h4&gt;Cloudflare&lt;/h4&gt;
&lt;p&gt;Many people use Fastly because it uses Varnish, a richly featured, programmable cache with several advanced features.
If you rely on those features, eg cache tags, cache on cookie value, custom cache tags, then you have to be on Cloudflare's
top plan, which is not cheap.&lt;/p&gt;
&lt;p&gt;The other major drawback of Cloudflare is that, unless you are on the most expensive plans, you have to cede control of
DNS to them by delegating your domain. Cloudflare DNS is a great service, however it has the major drawback of caching
negative DNS requests for an hour. If you were switching from an A record to a CNAME record or vice versa, you could be
down for an hour regardless. Not ideal.&lt;/p&gt;
&lt;h4&gt;Akamai&lt;/h4&gt;
&lt;p&gt;Akamai has a highly respected, fully featured, and very expensive product. Maintaining a backup option with them will run
into the $1000s a month. Only you can decide whether it’s worth it.&lt;/p&gt;
&lt;h4&gt;Cloudfront&lt;/h4&gt;
&lt;p&gt;Amazon's CDN offering is the third of the big three alternatives. Since it uses volume based billing, it could be an
attractive CDN option as a standby, as long as you don't mind missing out on cache by tag (sorry Magento and Drupal). It
is also complicated to configure for dynamic content and could miss features that you need. In fact most people use
Cloudfront for static content, eg images, CSS, etc and run a Varnish instance within AWS to provide easier to configure
full page caching.&lt;/p&gt;
&lt;p&gt;This is what the BBC did with the Fastly outage. They had their backup infrastructure on Cloudfront and, as of time of
writing, hadn't switched back to Fastly.&lt;/p&gt;
&lt;h4&gt;Peakhour.io&lt;/h4&gt;
&lt;p&gt;Peakhour is also volume based billing with a minimum monthly charge of $20. We provide all the advanced caching features
that Fastly does, as well as WAF and image optimisation as standard, all in the one service fee. We don't require you
to cede control of DNS to us and we're Australian owned and based.&lt;/p&gt;
&lt;h2&gt;Final Thoughts&lt;/h2&gt;
&lt;p&gt;CDNs, no matter how big, can fail. If your website is important then it needs a Plan B. This is how that Plan B works,
and it doesn't have to be expensive when using a provider like Peakhour.io.&lt;/p&gt;
&lt;p&gt;The important part is having it configured and tested before you need it.&lt;/p&gt;</content><category term="Interest"></category><category term="CDN"></category><category term="DDoS"></category><category term="DNS"></category><category term="Residential Proxies"></category></entry><entry><title>Setting Up A Chia Hobby Farm</title><link href="https://www.peakhour.io/blog/setting-up-a-chia-hobby-farm/" rel="alternate"></link><published>2021-04-30T13:00:00+10:00</published><updated>2021-04-30T13:00:00+10:00</updated><author><name>Dan</name></author><id>tag:www.peakhour.io,2021-04-30:/blog/setting-up-a-chia-hobby-farm/</id><summary type="html">&lt;p&gt;Chia is a new blockchain aiming to one up Bitcoin that's taking the crypto world by storm. We decided to jump on the bandwagon.&lt;/p&gt;</summary><content type="html">&lt;p&gt;Here at Peakhour, when we're not making websites faster and more secure, we like new tech and we like a good scheme. We ran Seti@home while at uni,
and mined some bitcoin back in its early days (unfortunately we don’t have them anymore). Just recently we
decided to set up a Chia farm, not the super-food Chia, but the new crypto coin Chia!&lt;/p&gt;
&lt;h2&gt;What is Chia?&lt;/h2&gt;
&lt;p&gt;Chia is not just a cryptocurrency; it is a brand new blockchain and smart transaction platform that implements the first new
&lt;a href="https://coinmarketcap.com/alexandria/article/what-is-the-nakamoto-consensus" target="new"&gt;Nakamoto consensus&lt;/a&gt; algorithm since Bitcoin.
It was invented by the engineer behind BitTorrent, Bram Cohen, who set out to address the shortcomings of Bitcoin.&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://www.chia.net" target="new"&gt;Chia network&lt;/a&gt; is set to officially launch on May 3rd, and the crypto world is going crazy getting ready.&lt;/p&gt;
&lt;h2&gt;I thought Bitcoin was great, what’s wrong with it?&lt;/h2&gt;
&lt;p&gt;The major flaws that Chia sets out to address are:&lt;/p&gt;
&lt;h3&gt;The environmental impact&lt;/h3&gt;
&lt;p&gt;Without getting too technical, Bitcoin relies on very intensive computations to verify transactions (Proof of work).
These computations are carried out by 'miners' who are rewarded for their efforts from an ever decreasing pool of
possible bitcoin. As the blockchain gets older, the verification gets harder, and as a result the Bitcoin network is now
consuming as much electricity as a &lt;a href="https://www.bloomberg.com/news/articles/2021-04-13/bitcoin-power-consumption-jumped-66-fold-since-2015-citi-says" target="new"&gt;mid-sized country like Argentina&lt;/a&gt;.
Huge mining operations have been set up in China,
and some even have dedicated power plants. One poster child for the environmental impacts of bitcoin is an Australian
startup looking to &lt;a href="https://www.cnet.com/news/blockchain-coal-power-plant-mining-bitcoin-cryptocurrency/" target="new"&gt;reopen a decommissioned coal power plant to power its mining operations&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Possibility of manipulation&lt;/h3&gt;
&lt;p&gt;The huge energy requirements have led to massive server farms in cool regions near cheap electricity, concentrating
mining in the hands of a few large players. This centralisation opens up Bitcoin to the possibility of manipulation
as anyone with 50% of the network can effectively change the blockchain.&lt;/p&gt;
&lt;h2&gt;How does Chia address these issues with Bitcoin?&lt;/h2&gt;
&lt;p&gt;Chia has implemented a new consensus algorithm called proof of space and time. It relies on unused hard disk space,
which lots of people have and can use free of charge. Again, without getting too technical, 'Farmers' seed unused
space on their hard drive/SSD with 'plots' of cryptographic numbers. When verifying transactions, the network issues a
challenge to the farmers, who then scan their plots for the closest answer. The farmer passes this answer back to a server on
the network known as a 'timelord'. The farmer with the closest answer is rewarded with a coin.&lt;/p&gt;
&lt;p&gt;The more 'plots' a farmer has, the higher the chance of winning a coin.&lt;/p&gt;
&lt;h2&gt;Setting up the Farm&lt;/h2&gt;
&lt;p&gt;We got excited about the idea of Chia being the next big thing and decided to hitch a ride on the bandwagon. We had a spare old
computer lying around, so we decided to fill it up with as much storage as we could find and farm some Chia!&lt;/p&gt;
&lt;p&gt;To set up a farm you need as much space for plots as you can get your hands on. The speed of this space
is not critical, so you can use spinning drives. We found 12-terabyte NAS drives to be the sweet spot for bang for buck,
and opted for 4x Seagate Ironwolf NAS drives from Scorptec. (Note: they’ve gone up $40 since we bought them!)&lt;/p&gt;
&lt;p&gt;Seeding the plots, however, is VERY disk intensive, so you need speedy and reliable SSDs. Since they don't have moving
parts you'd think that SSDs would be very reliable, but just like spinning drives, they wear out and eventually die.
SSDs come with a TBW (Terabytes Written) rating which estimates the amount of writes you can do before the drive will die.
Popular consumer SSDs like a 500GB Samsung EVO 870 have a TBW rating of 300. Chia recommends getting server-grade SSDs
that have ratings into the Petabytes, but of course they come with a price to match.&lt;/p&gt;
&lt;p&gt;We were limited by the age of our available motherboard, so we could only choose from SATA3-compatible drives. Appropriate enterprise
SSDs were also unavailable, so in the end we settled on 500GB Seagate Firecuda 120s that are rated at 700 TBW (also
from Scorptec). We decided on two so we could double the plotting rate.&lt;/p&gt;
&lt;p&gt;Now we had our hands on the drives, we just had to install everything. Within a few hours of transferring components and
wiring it up we were good to go and started plotting.&lt;/p&gt;
&lt;div class="text-center"&gt;
&lt;img src="/static/images/blog/chia-farm.jpg" alt="HTTP Request Detail" style="width: 60%;" /&gt;&lt;br/&gt;
&lt;em&gt;Our Chia Farm!&lt;/em&gt;
&lt;/div&gt;

&lt;h2&gt;Final Thoughts&lt;/h2&gt;
&lt;p&gt;Our old hardware limits the speed of the SSDs and therefore the number of plots we generate. We're managing around 10 plots a day and will need close to 500 before we’ve filled the available storage.&lt;/p&gt;
&lt;p&gt;When we bought our equipment (28th April) the &lt;a href="https://chiacalculator.com/" target="new"&gt;chia calculator&lt;/a&gt; showed
that we’d be earning around a coin a day when fully plotted. However, with the official launch of Chia imminent, the network has exploded in growth, passing 1 Exabyte (1000 Terabytes) just one day ago. It's now up to 1.68 Exabytes! So unfortunately our estimated time to a coin is down to one every 7 days. That’s still pretty good though, and if Chia does end up supplanting Bitcoin we might just make back the setup costs.
It has been a fun exercise, even if we did spend too long on it, and if it does end up being a flash in the pan we can always use the drives for something else….&lt;/p&gt;</content><category term="Interest"></category><category term="Features"></category><category term="Machine Learning"></category><category term="Networking"></category><category term="Residential Proxies"></category><category term="TLS"></category><category term="CDN"></category></entry></feed>